{"id":"CVE-2026-47722","aliases":["GHSA-7hp6-g3pq-3pc3","GO-2026-5223"],"url":"https://o3.security/vulnerability/CVE-2026-47722","summary":"nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml","details":"nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the operator-supplied `ListenHost` and `TunDevice` fields raw into a `text/template` that produces the agent's `config.yml`. `internal/web/advanced.go:20-35` accepts both with only `strings.TrimSpace` — no character or shape validation. Version 0.3.2 fixes the issue.","published":"2026-07-23T19:19:41.976Z","modified":"2026-08-12T03:51:37.270746119Z","cvss":null,"epss":{"score":0.00467,"percentile":0.38726,"asOf":"2026-09-02"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/juev/nebula-mesh","fixedVersion":"0.3.2"}],"fix":{"url":"https://github.com/forgekeep/nebula-mesh/commit/c1506f7344ab375a145a7449b193af3f19bb41ef","label":"forgekeep/nebula-mesh@c1506f7"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47722.json"},{"type":"ADVISORY","url":"https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-7hp6-g3pq-3pc3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47722"},{"type":"REPORT","url":"https://github.com/forgekeep/nebula-mesh/issues/126"},{"type":"FIX","url":"https://github.com/forgekeep/nebula-mesh/commit/c1506f7344ab375a145a7449b193af3f19bb41ef"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:37.270746119Z"}}